Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

276 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)2.3%—Microsoft Visual Studio Code Kubernetes Tools13/4/202117/6/2026
Visual Studio Code Kubernetes Tools Remote Code Execution Vulnerability
ModificadaAlta (7.4)1.3%—Redhat Kubernetes-clientRedhat A-mq OnlineRedhat Build OF QuarkusRedhat Codeready Studio+516/3/202117/6/2026
A flaw was found in the fabric8 kubernetes-client in version 4.2.0 and after. This flaw allows a malicious pod/container to cause applications using the fabric8 kubernetes-client `copy` command to extract files outside the working path. The highest threat from this vulnerability is to integrity and system…
ModificadaMedia (6.8)1.4%—Microsoft Azure Container InstancesMicrosoft Azure Container RegistryMicrosoft Azure Kubernetes ServiceMicrosoft Azure Service Fabric+111/3/202119/8/2026
Azure Virtual Machine Information Disclosure Vulnerability
ModificadaMedia (6.8)2.2%—Microsoft Azure Kubernetes Service25/2/202117/6/2026
Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability
ModificadaCrítica (9.1)3.6%💥 PoCKubernetes Java21/1/202117/6/2026
Kubernetes Java client libraries in version 10.0.0 and versions prior to 9.0.1 allow writes to paths outside of the current directory when copying multiple files from a remote pod which sends a maliciously crafted archive. This can potentially overwrite any files on the system of the process executing the client code.
ModificadaMedia (6.5)2.3%—Kubernetes Container Storage Interface Snapshotter21/1/202117/6/2026
Kubernetes CSI snapshot-controller prior to v2.1.3 and v3.0.2 could panic when processing a VolumeSnapshot custom resource when: - The VolumeSnapshot referenced a non-existing PersistentVolumeClaim and the VolumeSnapshot did not reference any VolumeSnapshotClass. - The snapshot-controller crashes, is automatically…
ModificadaMedia (6.5)1.3%—Kubernetes Secrets Store CSI Driver21/1/202117/6/2026
Kubernetes Secrets Store CSI Driver versions v0.0.15 and v0.0.16 allow an attacker who can modify a SecretProviderClassPodStatus/Status resource the ability to write content to the host filesystem and sync file contents to Kubernetes Secrets. This includes paths under var/lib/kubelet/pods that contain other Kubernetes…
ModificadaMedia (5)9.3%💥 PoCKubernetesOracle Communications Cloud Native Core Network Slice Selection FunctionOracle Communications Cloud Native Core PolicyOracle Communications Cloud Native Core Service Communication Proxy21/1/202117/6/2026
Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Additionally, an attacker who is able to patch the status (which is considered a privileged operation and should not typically be granted to…
ModificadaMedia (5.5)1.2%—Microsoft Azure Kubernetes Service12/1/202117/6/2026
Azure Active Directory Pod Identity Spoofing Vulnerability
ModificadaMedia (5.5)0.53%—Kubernetes7/12/202017/6/2026
In Kubernetes clusters using Ceph RBD as a storage provisioner, with logging level of at least 4, Ceph RBD admin secrets can be written to logs. This occurs in kube-controller-manager's logs during provisioning of Ceph RBD persistent claims. This affects < v1.19.3, < v1.18.10, < v1.17.13.
ModificadaMedia (5.5)0.52%—Kubernetes7/12/202017/6/2026
In Kubernetes, if the logging level is set to at least 9, authorization and bearer tokens will be written to log files. This can occur both in API server logs and client tool output like kubectl. This affects <= v1.19.3, <= v1.18.10, <= v1.17.13, < v1.20.0-alpha2.
ModificadaMedia (5.5)0.46%—Kubernetes7/12/202017/6/2026
In Kubernetes clusters using a logging level of at least 4, processing a malformed docker config file will result in the contents of the docker config file being leaked, which can include pull secrets or other registry credentials. This affects < v1.19.3, < v1.18.10, < v1.17.13.
ModificadaMedia (5.5)0.51%—Kubernetes7/12/202017/6/2026
In Kubernetes clusters using VSphere as a cloud provider, with a logging level set to 4 or above, VSphere cloud credentials will be leaked in the cloud controller manager's log. This affects < v1.19.3.
ModificadaBaja (3.5)0.25%—Redhat Advanced Cluster Management FOR Kubernetes23/11/202017/6/2026
A flaw was found in rhacm versions before 2.0.5 and before 2.1.0. Two internal service APIs were incorrectly provisioned using a test certificate from the source repository. This would result in all installations using the same certificates. If an attacker could observe network traffic internal to a cluster, they…
ModificadaMedia (6.5)0.61%—Redhat Advanced Cluster Management FOR Kubernetes9/11/202017/6/2026
An issue was discovered in ManagedClusterView API, that could allow secrets to be disclosed to users without the correct permissions. Views created for an admin user would be made available for a short time to users with only view permission. In this short time window the user with view permission could read cluster…
ModificadaMedia (4.3)1.1%—Jenkins Kubernetes4/11/202017/6/2026
A missing/An incorrect permission check in Jenkins Kubernetes Plugin 1.27.3 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
ModificadaMedia (4.3)1.2%—Jenkins Kubernetes4/11/202017/6/2026
A missing permission check in Jenkins Kubernetes Plugin 1.27.3 and earlier allows attackers with Overall/Read permission to list global pod template names.
ModificadaMedia (4.3)1.3%—Jenkins Kubernetes4/11/202017/6/2026
Jenkins Kubernetes Plugin 1.27.3 and earlier allows low-privilege users to access possibly sensitive Jenkins controller environment variables.
ModificadaMedia (5.9)0.89%—Kubernetes Ingress-nginx29/7/202017/6/2026
The Kubernetes ingress-nginx component prior to version 0.28.0 allows a user with the ability to create namespaces and to read and create ingress objects to overwrite the password file of another ingress which uses nginx.ingress.kubernetes.io/auth-type: basic and which has a hyphenated namespace or secret name.
ModificadaAlta (8.8)3.6%💥 PoCKubernetes27/7/202017/6/2026
The Kubelet and kube-proxy components in versions 1.1.0-1.16.10, 1.17.0-1.17.6, and 1.18.0-1.18.3 were found to contain a security issue which allows adjacent hosts to reach TCP and UDP services bound to 127.0.0.1 running on the node or in the node's network namespace. Such a service is generally thought to be…
ModificadaMedia (5.5)0.50%—Kubernetes23/7/202017/6/2026
The Kubernetes kubelet component in versions 1.1-1.16.12, 1.17.0-1.17.8 and 1.18.0-1.18.5 do not account for disk usage by a pod which writes to its own /etc/hosts file. The /etc/hosts file mounted in a pod by kubelet is not included by the kubelet eviction manager when calculating ephemeral storage usage by a pod. If…
ModificadaMedia (6.5)1.2%—Kubernetes23/7/202017/6/2026
The Kubernetes kube-controller-manager in versions v1.0-v1.17 is vulnerable to a credential leakage via error messages in mount failure logs and events for AzureFile and CephFS volumes.
ModificadaMedia (6.8)6.1%💥 PoCKubernetes22/7/202017/6/2026
The Kubernetes kube-apiserver in versions v1.6-v1.15, and versions prior to v1.16.13, v1.17.9 and v1.18.6 are vulnerable to an unvalidated redirect on proxied upgrade requests that could allow an attacker to escalate privileges from a node compromise to a full cluster compromise.
ModificadaAlta (8.8)2.3%—Jenkins Kubernetes CI2/7/202017/6/2026
Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin 1.3 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.
ModificadaMedia (6.3)3.7%—KubernetesFedoraproject Fedora5/6/202017/6/2026
The Kubernetes kube-controller-manager in versions v1.0-1.14, versions prior to v1.15.12, v1.16.9, v1.17.5, and version v1.18.0 are vulnerable to a Server Side Request Forgery (SSRF) that allows certain authorized users to leak up to 500 bytes of arbitrary information from unprotected endpoints within the master's…